Privacy Policy
Last updated: August 23, 2026
TakeAPik (“TakeAPik,” “we,” “us”) provides private, event-scoped photo albums. This policy explains what we collect, why, how we protect it, and the choices you have. It applies to the TakeAPik website and service at takeapik.com. The service is operated by Brand Works Media LLC, 2125 Biscayne Blvd Ste 204-21559, Miami, FL 33137, reachable at privacy@brandworksmedia.com.
1. The roles involved
Each album belongs to an event host (the album administrator) who invites guests to view and add photos. For the personal data inside an album, the host is the party who decides what is collected and why; TakeAPik processes that data on their behalf and for operating the service. If you are a guest with questions about a specific album, contact its host first; you may also contact us.
2. Information we collect
- Account information (hosts): name, email address, and a password (stored only as a strong one-way hash). Hosts may enable two-factor authentication.
- Guest membership information: the name and email address a host adds for each guest, used to send invitations and to sign guests in.
- Event information: event name, event date, and an access code that guests use to enter the album.
- Photos and captions: images uploaded to an album and any optional descriptions. Images are resized on your device before upload, and location (GPS) and other metadata are stripped in the process — original camera metadata is not uploaded.
- Technical and security data: we log request identifiers, coarse actor and tenant identifiers, route, timing, and outcome, plus one-way hashes of IP address and user agent for abuse prevention. We do not log photos, access codes, passwords, tokens, email contents, or signed media URLs.
We do not use third-party advertising or analytics trackers, and we do not sell personal information.
3. How we use information
- To create and operate albums, sign users in, and deliver invitation, welcome, and password-reset emails.
- To store, resize-verify, and serve album photos to the album’s members.
- To secure the service — rate limiting, abuse detection, audit logging of privileged actions.
- To communicate service and security notices.
4. How photos are stored and shared
Photos are held in private object storage and served only through short-lived signed links to signed-in members of the same album. Albums are isolated from one another: a session is bound to a single album, and every request is checked against that binding. Albums are not publicly listed or searchable, and knowing a link alone does not grant access without a valid membership and access code.
5. Email and credentials
Invitation and onboarding emails include the album’s access code so guests can sign in easily. Because of this, a person with access to an invited guest’s mailbox could open that album; treat these emails as you would any message containing a login credential. Hosts can rotate the access code at any time, which immediately invalidates the old one.
6. Retention and deletion
Albums are event-scoped. Uploads open about one week before the event date and the album stays available for 90 days afterward, after which it is flagged for takedown. Hosts can export their photos before the window closes. A host or the platform can delete an album’s contents (permanently removing photos from the database and storage) or delete an account entirely. Deletion is permanent and cannot be undone except from backups, which are themselves retained for a limited period and then expire. Security audit logs are retained for as long as applicable law requires, and no longer than necessary for security and legal purposes.
7. Your rights and choices
Depending on where you live, you may have rights to access, correct, export, or delete your personal data, and to object to or restrict certain processing. Hosts can manage guest data directly in their album settings. For other requests, contact privacy@brandworksmedia.com; we will respond within the period required by applicable law. You can decline non-essential cookies; TakeAPik uses only the strictly necessary cookie that keeps you signed in.
8. Security
We use HTTPS everywhere, a strict Content-Security-Policy, one-way hashing for passwords and tokens, encryption for sensitive stored values, host-only session cookies, and audit logging of privileged actions. No system is perfectly secure, but album isolation and least-privilege access are core to the design.
9. International transfers, children, and changes
Data is processed in the United States. TakeAPik is not directed to children under 16, and hosts are responsible for any consent needed to include a minor’s photo. We may update this policy; material changes will be posted here with a new date.
Terms of Service
Last updated: August 23, 2026
1. Agreement
By using TakeAPik you agree to these terms. If you use TakeAPik on behalf of an organization, you agree on its behalf. If you do not agree, do not use the service.
2. Accounts and eligibility
Hosts must provide accurate information, keep their password and two-factor credentials secure, and are responsible for activity under their account. You must be at least 16 and legally able to enter this agreement.
3. Acceptable use
You agree not to:
- Upload content you do not have the right to share, or that is unlawful, infringing, or harmful.
- Upload photos of people without the consent required where the event takes place.
- Attempt to access albums, accounts, or data that are not yours, or probe, scan, or circumvent security.
- Interfere with the service, overload it, or use it to send spam or malware.
4. Your content
You keep ownership of the photos and captions you upload. You grant TakeAPik the limited license needed to store, resize, and display that content to your album’s members and to operate and secure the service. You are responsible for your content and for having the rights and consents to share it.
5. Hosts and guests
Hosts control their album’s membership, access code, event details, and content, and may remove guests or photos and export or delete the album. Guests may add and manage their own uploads and view the album while their membership is active. Access can be revoked at any time.
6. Availability, retention, and deletion
The service is provided on an ongoing basis but may change or have downtime. Albums follow the retention window described in the Privacy Policy. We may remove content or suspend accounts that violate these terms. Deletion is permanent as described above.
7. Disclaimers and liability
TakeAPik is provided “as is,” without warranties of any kind to the fullest extent permitted by law. We are not liable for indirect, incidental, or consequential damages, and our total liability is limited to the amount you paid us in the 12 months before the claim, and where you paid nothing, TakeAPik has no monetary liability to you. Some jurisdictions do not allow these limits, so parts may not apply to you.
8. Changes, termination, and governing law
We may update these terms; continued use means acceptance. Either party may terminate; on termination your right to use the service ends and album retention/deletion applies. These terms are governed by the laws of the State of Florida. Disputes will first be resolved through binding arbitration seated in Florida before either party pursues any court action, except where such arbitration is not permitted by law.
9. Contact
Questions about these terms or your data: privacy@brandworksmedia.com.